CVE detail
CVE-2026-46300
In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to @to. If @from has SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same externally-owned or page-cache-backed frags, but the shared-frag marker is currently lost. That breaks the invariant relied on by later in-place writers. In particular, ESP input checks skb_has_shared_frag() before deciding whether an uncloned nonlinear skb can skip skb_cow_data(). If TCP receive coalescing has moved shared frags into an unmarked skb, ESP can see skb_has_shared_frag() as false and decrypt in place over page-cache backed frags. Propagate SKBFL_SHARED_FRAG when skb_try_coalesce() transfers paged frags. The tailroom copy path does not need the marker because it copies bytes into @to's linear data rather than transferring frag descriptors.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
62 source links · newest first
00 CPU 1518(F)-4 PN/DP MFP are affected: SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) vers:intdot/>=3.1.6 (CVE-2021-41617, CVE-2023-28531, CVE-2023-51384, CVE-2023-52927, CVE-2024-26783, CVE-2024-27056, CVE-2024-28956, CVE-2024-36903, CVE-2024-36927, CVE-2024-42079, CVE-2024-46786, CVE-2024-47736, CVE-2024-47809, CVE-2024-49968, CVE-2024-4
governmentwww.cisa.govJul 28, 2026, 12:00 PMA variant of DirtyFrag, the flaw allows unprivileged local users to manipulate the Linux page cache and gain root privileges.
newswww.securityweek.comJun 29, 2026, 11:20 AMDirtyClone: a Linux kernel privilege escalation that silently rewrites executables in memory, leaving no disk trace. Patch now. JFrog Security Research published a working exploit walkthrough on June 25 for CVE-2026-43503 (CVSS score of 8.8), a Linux kernel privilege escalation they call DirtyClone. It’s the fourth vulnerability in the DirtyFrag family, all sharing the same […]
newssecurityaffairs.comJun 27, 2026, 9:12 AMCVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:H/RC:C CVE-2026-43284 In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_
governmentwww.cisa.govJun 23, 2026, 12:00 PMInformation published.
vendormsrc.microsoft.comMay 27, 2026, 8:01 AM- https://cert-portal.siemens.com/productcert/html/ssa-082556.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comMay 23, 2026, 12:17 PM - https://cert-portal.siemens.com/productcert/html/ssa-019113.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comMay 23, 2026, 12:17 PM - https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46300.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comMay 23, 2026, 12:17 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2477015bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/security/cve/CVE-2026-46300access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:34098access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:33486access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:28887access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:25044access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:24814access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:23471access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:23470access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:23469access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:23468access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:23245access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:23240access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:23233access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:21702access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:21695access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:21690access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:21656access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:20593access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:20299access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:20130access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:20129access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:20087access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:20054access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:20051access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:19875access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:19711access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:19705access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:19666access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:19664access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:19569access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:19568access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:19540access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHSA-2026:19521access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - https://access.redhat.com/errata/RHBA-2026:20032access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 23, 2026, 12:17 PM - http://www.openwall.com/lists/oss-security/2026/05/21/13www.openwall.com
No excerpt available.
Exploitwww.openwall.comMay 23, 2026, 12:17 PM - http://www.openwall.com/lists/oss-security/2026/05/21/12www.openwall.com
No excerpt available.
Exploitwww.openwall.comMay 23, 2026, 12:17 PM - http://www.openwall.com/lists/oss-security/2026/05/21/11www.openwall.com
No excerpt available.
Exploitwww.openwall.comMay 23, 2026, 12:17 PM - http://www.openwall.com/lists/oss-security/2026/05/13/5www.openwall.com
No excerpt available.
Exploitwww.openwall.comMay 23, 2026, 12:17 PM No excerpt available.
Vendor Advisorygit.kernel.orgMay 23, 2026, 12:17 PMNo excerpt available.
Vendor Advisorygit.kernel.orgMay 23, 2026, 12:17 PMNo excerpt available.
Vendor Advisorygit.kernel.orgMay 23, 2026, 12:17 PMNo excerpt available.
Vendor Advisorygit.kernel.orgMay 23, 2026, 12:17 PMNo excerpt available.
Vendor Advisorygit.kernel.orgMay 23, 2026, 12:17 PMNo excerpt available.
Vendor Advisorygit.kernel.orgMay 23, 2026, 12:17 PMNo excerpt available.
Vendor Advisorygit.kernel.orgMay 23, 2026, 12:17 PMNo excerpt available.
Vendor Advisorygit.kernel.orgMay 23, 2026, 12:17 PM- DirtyDecrypt: PoC Released for yet another Linux flawSecurity Affairs
DirtyDecrypt (CVE-2026-31635): working PoC out for a Linux kernel LPE flaw. Missing COW guard in rxgk_decrypt_skb lets local attackers reach root. After Copy Fail, Dirty Frag, and Fragnesia, here comes DirtyDecrypt, another local privilege escalation vulnerability in the kernel, this time with a working proof-of-concept already out in the open. The flaw was discovered and […]
newssecurityaffairs.comMay 20, 2026, 7:36 AM Patched in April, the underlying vulnerability allows local attackers to elevate their privileges to root.
newswww.securityweek.comMay 19, 2026, 9:42 AM- Week in review: Cisco patches SD-WAN 0-day, unpatched Microsoft Exchange Server flaw exploitedHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Review: Foundations of Cybersecurity, 2nd edition Jason Andress has refreshed his introductory security text for No Starch Press. He writes in the introduction that the term security now extends past data center servers to cloud resources, mobile devices, the Internet of Things, and AI. Foundations of Cybersecurity: A Straightforward Introduction book is aimed at newcomers to the field, network and … More →
newswww.helpnetsecurity.comMay 17, 2026, 8:00 AM Linux admins reeling from handling last month’s CopyFail and last week’s Dirty Frag kernel vulnerabilities have a new headache to deal with: Fragnesia. “This is a significant vulnerability,” Robert Beggs, head of incident response firm DigitalDefence, told CSO. “It is bypassing traditional filesystem permissions that are present and enforced (for example, ‘file is owned by […]
newswww.csoonline.comMay 14, 2026, 8:29 PM- Linux Kernel bug Fragnesia allows local root access attacksSecurity Affairs
Fragnesia, a new Linux kernel flaw tracked as CVE-2026-46300, could let local attackers gain root access through page cache corruption. Researchers disclosed a new Linux kernel privilege escalation vulnerability named Fragnesia, tracked as CVE-2026-46300 (CVSS score of 7.8). The flaw affects the XFRM ESP-in-TCP subsystem and could allow local attackers to gain full root access […]
newssecurityaffairs.comMay 14, 2026, 5:57 PM - Fragnesia: New Linux kernel LPE bug was spawned by Dirty Frag patch (CVE-2026-46300)Help Net Security
Researchers have found and disclosed yet another local privilege escalation (LPE) vulnerability in the Linux kernel: CVE-2026-46300, aka “Fragnesia”. The flaw is in the same class of vulnerabilities as the recently disclosed Dirty Frag bug(s). Like Dirty Frag, it affects the same Linux module (xfrm-ESP). In fact, according to Dirty Frag discoverer Hyunwoo Kim, Fragnesia was “accidentally activated” by the patch fixing one of the original Dirty Frag vulnerabilities (i.e., CVE-2026-43284). CVE-2026-46300 explained Fragnesia was … More →
newswww.helpnetsecurity.comMay 14, 2026, 2:34 PM The vulnerability, tracked as CVE-2026-46300, is similar to the recently disclosed exploits named Dirty Frag and Copy Fail.
newswww.securityweek.comMay 14, 2026, 1:44 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-43500CVSS 7.8 · High
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present The DATA-packet handler in rxrpc_input…
- CVE-2026-25634CVSS 7.8 · High
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to 2.3.1.4, SrcPixel and DestPix…
- CVE-2025-62164CVSS 8.8 · High
vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memory corruption vulnerability could lead to a crash (denial-of…
- CVE-2025-22225CVSS 8.2 · High
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the s…
- CVE-2024-20141CVSS 6.6 · Medium
In V5 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device…
- CVE-2024-47438CVSS 5.5 · Medium
Substance3D - Painter versions 10.1.0 and earlier are affected by a Write-what-where Condition vulnerability that could lead to a memory leak. This vulnerability allows an attacke…